CLM & PKI AUTOMATION PLATFORM
Every certificate. One control plane.
ens0key discovers, inventories, and automates the lifecycle of every X.509 certificate in your organization — and runs the PKI behind it: your own issuing CA with CRL/OCSP, external CA connectors, and agents that deploy and renew certificates hands-free.
Three problems. One platform.
Certificate outages, untracked keys, and manual renewals — ens0key covers the full machine-identity lifecycle.
Certificate lifecycle
Know every certificate you have, where it lives, and when it expires — before it takes production down.
- ▸Network discovery of targets and CIDR ranges, plus agent-side discovery
- ▸Inventory deduplicated by SHA-256 fingerprint with observation history
- ▸Automatic flags: expired, expiring, self-signed, weak key, SHA-1
- ▸Expiry alerts via e-mail digests and Slack-compatible webhooks
PKI automation
Issue, renew, and revoke from one place — whether the CA is yours or someone else's.
- ▸Built-in issuing CA with a real CRL and OCSP responder
- ▸Connectors for ACME (RFC 8555), DigiCert CertCentral, and EJBCA
- ▸Encrypted key vault: AES-256-GCM envelope encryption, KMS/HSM-ready
- ▸Optional approval workflow before anything gets issued
Hands-free deployment
Agents put renewed certificates where they belong and reload the services that use them.
- ▸Pull-model agents over mTLS — no inbound connections, NAT-friendly
- ▸PEM, PKCS#12, and JKS certificate stores
- ▸Auto-renewal with reload hooks and service verification
- ▸Blueprints for mass rollout across your fleet
Built for operators
Expiry heatmap, CA breakdown, key-strength report — inventory health at a glance, in designed dark and light themes.

The ens0key dashboard — the landing page of your certificate estate.


Enterprise-grade from the first login
SSO & LDAP
OIDC sign-in with a Microsoft Entra ID preset, LDAPS, and a local break-glass admin.
RBAC
Viewer, operator, and admin roles mapped from SSO/LDAP groups — enforced server-side.
Audit log
Every mutation and every login attempt, recorded.
Backup & restore
Scheduled encrypted dumps to local, SFTP, SCP, or TFTP repositories; transactional in-app restore.
See ens0key on your own estate
A pilot takes one server and one PostgreSQL database. We'll help you scan your first ranges the same day.
Talk to us